Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    new pfsense firewall blocks many websites

    Scheduled Pinned Locked Moved General pfSense Questions
    20 Posts 9 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pirod
      last edited by pirod

      Hi,

      I have a new pfsense netgate 4100, the firewall all permissive (no rules yet) and many web sites are blocked by default:

      Ex:
      Dec 6 18:16:41 LAN 192.168.1.120:57232 104.18.39.73:443 TCP:A

      Dec 6 18:17:55 WAN 192.168.1.254 224.0.0.1 IGMP

      so sites like ikea.com, slack.com, and many others are refused by the firewall. I can go to google.com and netgate forum...

      I see many people complaining the same and no real answers are given. What is the way to put the firewall permissive and then start adding rules?

      2022-12-06_18h23_21.png

      thanks
      Pierre

      R johnpozJ NogBadTheBadN 3 Replies Last reply Reply Quote 0
      • R
        rcoleman-netgate Netgate @pirod
        last edited by

        @pirod What DNS servers are configured?

        What is DHCP handing out?

        How is pfSense configured to handle DNS?

        There was a report earlier about slack and sites being blocked but it was tracked down to OpenDNS blocking it.

        Ryan
        Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
        Requesting firmware for your Netgate device? https://go.netgate.com
        Switching: Mikrotik, Netgear, Extreme
        Wireless: Aruba, Ubiquiti

        P 1 Reply Last reply Reply Quote 0
        • P
          pirod @rcoleman-netgate
          last edited by

          @rcoleman-netgate
          thanks for replying. Not sure OpenDNS was for me. I don't have it.

          DNS are full automatic give by ATT router.

          G 1 Reply Last reply Reply Quote 0
          • G
            gabacho4 Rebel Alliance @pirod
            last edited by

            @pirod can you provide screenshots of your firewall rule tabs?

            GertjanG 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @pirod
              last edited by johnpoz

              @pirod said in new pfsense firewall blocks many websites:

              I see many people complaining the same and no real answers are given

              Where do you see these complaints of the same thing? All of your blocks are out of state - they are ACKS, these are common to see in asymmetrical or when states have been reset do to say a loss of wan connectivity when you have pfsense set to reset states.

              Your block of IGMP on your wan would be a given to be blocked and logged by the default rule on wan that blocks rfc1918 states, and just by the nature that nothing is allowed by default on the wan.. Why would you think IGMP being blocked would have anything to do with your issue?

              IGMP would have zero use on pfsense wan that is for sure.. It is multicast..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad @pirod
                last edited by NogBadTheBad

                @pirod Add the following to Status -> System Logs -> Firewall -> Normal View click on the wrench / spanner.

                Screenshot 2022-12-07 at 08.46.22.png

                You'll get a description of the rule its failing on.

                The last 3 log entires suggest you have a router connected to the internet then your pfSense router as the source IP address is in the RFC1918 range.

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                1 Reply Last reply Reply Quote 0
                • GertjanG
                  Gertjan @gabacho4
                  last edited by

                  @gabacho4 said in new pfsense firewall blocks many websites:

                  can you provide screenshots of your firewall rule tabs?

                  +1 that one.

                  Look at the picture already included :

                  6c2e4bbd-a7ef-4140-8427-1644d800cb64-image.png

                  There is a USER created firewall rule called "Bock all IN".
                  Bock .....
                  @Pirod : serious ? ๐Ÿ˜Š

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  P 1 Reply Last reply Reply Quote 0
                  • P
                    pirod @Gertjan
                    last edited by pirod

                    @gertjan wel ok, that was a test rule, but the issue is not related. I removed it again and still:

                    2022-12-07_06h47_34.png

                    But as you see I can reply to this post on the forum. Google works. But a bunch of websites and apps are keeping to be blocked.

                    ERR_NAME_NOT_RESOLVED

                    Maybe a DNS issue but I tested even using google DNS.

                    The details on normal vue:
                    2022-12-07_06h53_10.png

                    So I guess it is NOT the firewall preventing. But maybe more something related to how the WAN uses DNS from router from ATT?

                    S johnpozJ 2 Replies Last reply Reply Quote 0
                    • S
                      SteveITS Galactic Empire @pirod
                      last edited by

                      @pirod A couple thoughts...

                      In your AT&T router, enable the Passthrough setting and select your pfSense, so your pfSense gets a public IP address.

                      In your pfSense DNS Resolver settings, uncheck "DNS Query Forwarding" and pfSense will resolve domains itself, without using AT&T DNS servers. (Unchecked is the default.)

                      Out of the box pfSense has only two rules, both on LAN, to allow from LAN to any (IPv4 and v6). So either additional block rules were added, or the problem is something else, like DNS.

                      ikea.com [104.108.110.251] is pingable...try pinging it by its IP address.

                      Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                      When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                      Upvote ๐Ÿ‘ helpful posts!

                      P 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @pirod
                        last edited by

                        @pirod looks like a dns problem to me.. from this client what do you get when you do say from cmd prompt

                        nslookup www.ikea.com

                        $ nslookup www.ikea.com
                        Server:  pi.hole
                        Address:  192.168.3.10
                        
                        Non-authoritative answer:
                        Name:    e11632.x.akamaiedge.net
                        Address:  104.114.25.189
                        Aliases:  www.ikea.com
                                  san.ov11632.ikea.com.edgekey.net
                        

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • P
                          pirod @SteveITS
                          last edited by

                          @steveits
                          Thanks for the reply. I changed to passthrough and DNS resolver was like you said.

                          Still cannot ping site like idea.com:
                          2022-12-07_19h59_21.png

                          S S Cool_CoronaC 3 Replies Last reply Reply Quote 0
                          • S
                            skogs @pirod
                            last edited by skogs

                            Things ~should~ resolve either way, but since we're having issues I would at least test turning on the DNS Query Forwarding.
                            IIRC the docs don't mention it, but when off the system just spams the root dns servers instead of anything manually set. I don't consider myself fancy enough to bother the root dns servers.

                            I feel like that last screenshot shows us getting worse ...
                            clearly some resolution happened, and that is a valid IP, but the pings should function. I just tested it myself as well as several others for ikea.

                            I'm almost leaning toward modem mac filter, passthrough not functioning, or still just plain wrong WAN side setup with an incorrect subnet setup. Perhaps a static set IP but accidentally did wrong subnet?

                            GertjanG 1 Reply Last reply Reply Quote 0
                            • S
                              SteveITS Galactic Empire @pirod
                              last edited by

                              @pirod Try a traceroute and see how far it gets. Also try the IP I showed above.

                              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                              Upvote ๐Ÿ‘ helpful posts!

                              1 Reply Last reply Reply Quote 0
                              • Cool_CoronaC
                                Cool_Corona @pirod
                                last edited by

                                @pirod Its a setup problem.... not related to anything external.

                                Give me a teamviewer and access to tyour pfsense for 5 min and I will solve it for you.

                                1 Reply Last reply Reply Quote 0
                                • GertjanG
                                  Gertjan @skogs
                                  last edited by

                                  @skogs said in new pfsense firewall blocks many websites:

                                  I don't consider myself fancy enough to bother the root dns servers.

                                  But you are.

                                  When you decide to forward to some commercial data collector center, sorry, a DNS server like 1.1.1.1, you mandate them to 'bother' the root servers, as these are where your DNS request starts.. Because 1.1.1.1, 8.8.8.8 etc are resolvers.
                                  So they will contact the root servers on your behalf.
                                  Then they contact a TLD DNS server.
                                  Then they contact a domain name server, who give you the answer of your request.

                                  So, why not, take the long road, do forwarding instead of your own resolving ๐Ÿ˜Š

                                  And I'm not done yet : there is more : your local 'unbound', while forwarding or resolving, is also caching the results obtained.
                                  Ones it knows from the root servers where it can find answers for "where are the dot com TLDs ?" it won't bother them anymore for do com requests (and dot net and dot org etc) as these are also cached.Results from the domain name servers are also cached.
                                  And true, the 1.1.1.1, 8.8.8.8 etc are also caching.

                                  IMHO, if you have a question, and you have the choice to get the answers from the eye witness, or from some one who 'knows about it', who would you ask the question ?
                                  Using the root servers, resolving, can give you a free bonus : when possible, it uses DNSSEC which guarantees you, that when you get an answer, it's a good answer, not a spoofed one. Forwarding means : you have to trust 1.1.1.1 or 8.8.8.8, as DNSSEC results are unknown to you.

                                  So, again, serious ? Doubting about 'do it yourself' or 'ask some one else' ?

                                  You mentioned ikea.com. If you were resolving, this would be the result : https://dnsviz.net/d/ikea.com/dnssec/ so ikea.com is fully DNSSEC aware, so I (my resolver) will know that the answers, an A, AAAA MX TXT or NS record, are correct.

                                  Btw : check your pfSense date and time. When it's not correct, DNSSEC will fail => DNS seems to fail.

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  johnpozJ 1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator @Gertjan
                                    last edited by johnpoz

                                    @gertjan said in new pfsense firewall blocks many websites:

                                    check your pfSense date and time. When it's not correct, DNSSEC will fail => DNS seems to fail.

                                    This is a good point - but from his ping he tried to ikea.com did resolve.. So its not a dns issue on pfsense part.

                                    It could be on his client having dns problem - maybe unbound isn't answering his clients? But that does not explain why his ping test from pfsense didn't work.

                                    Would be a good test to see traceroute from pfsense to this ikea.com.. for example.

                                    trace.jpg

                                    If fails with any, maybe change that to actual wan for interface to use as source.

                                    Also is there any vpn in in play here - users tend to leave out important pieces of the puzzle all the time.. For all we know he is going out a vpn, and those sites don't like his vpn and don't answer..

                                    edit: btw - he is not using IPv4 to talk to the forums? Only IPv6.. Possible piece to the puzzle in that as well.

                                    so be curious to see if his ping test works when he uses IPv6

                                    ping1.jpg

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                    P 1 Reply Last reply Reply Quote 0
                                    • P
                                      pirod @johnpoz
                                      last edited by

                                      seems to be fixed!!

                                      this was missing:2022-12-08_17h52_59.png

                                      johnpozJ 1 Reply Last reply Reply Quote 0
                                      • johnpozJ
                                        johnpoz LAYER 8 Global Moderator @pirod
                                        last edited by

                                        @pirod what did you have there?

                                        Kind of hard to get to lots of the internet if you don't have any IPv4 address that is for sure.

                                        www.ikea.com doesn't have IPv6 address.. Nor does www.slack.com

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                        P 1 Reply Last reply Reply Quote 0
                                        • P
                                          pirod @johnpoz
                                          last edited by

                                          @johnpoz
                                          was on static ipv4 I guess. Not sure why.

                                          Yes internet is not yet ful ipv6!

                                          THANK YOU ALL for your patience!!!

                                          johnpozJ 1 Reply Last reply Reply Quote 0
                                          • johnpozJ
                                            johnpoz LAYER 8 Global Moderator @pirod
                                            last edited by johnpoz

                                            @pirod said in new pfsense firewall blocks many websites:

                                            was on static ipv4 I guess. Not sure why.

                                            Well if it was static you would of had to have set the IP, etc It defaults to dhcp that is for sure.

                                            BTW - still waiting for where you see all the complaints with no answers ;)

                                            I see many people complaining the same and no real answers are given.

                                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                                            If you get confused: Listen to the Music Play
                                            Please don't Chat/PM me for help, unless mod related
                                            SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.